Skip to content

ci: SDK pipeline hardening using custom action and commit hashes instead of tags#53

Open
tuunit wants to merge 1 commit into
stackitcloud:mainfrom
tuunit:ci/workflow-pipeline-hardening
Open

ci: SDK pipeline hardening using custom action and commit hashes instead of tags#53
tuunit wants to merge 1 commit into
stackitcloud:mainfrom
tuunit:ci/workflow-pipeline-hardening

Conversation

@tuunit

@tuunit tuunit commented Jun 23, 2026

Copy link
Copy Markdown

In light of recent events on GitHub, NPM and the whole Open Source ecosystem we shouldn't rely on random github actions like shimataro/ssh-key-action@v2 for simple tasks such as adding an SSH key and known hosts. As well as use git commit hashes instead of tags to ensure we don't fall victim to a repository / org takeover as has happened with fake Trivy tags

…ead of tags

Signed-off-by: Jan Larwig <jan@larwig.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant